31 lines
1.3 KiB
Docker
31 lines
1.3 KiB
Docker
FROM ghcr.io/berriai/litellm:v1.103.2
|
|
|
|
# v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on
|
|
# /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth
|
|
# bypass, fixed 1.84.0, CISA KEV catalog). Pin the exact tag — do NOT
|
|
# use a floating tag like main-v1.74.0-stable, which silently moved.
|
|
|
|
# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only
|
|
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
|
|
# container, so we keep root to match the base image and avoid /app/data
|
|
# volume-ownership issues.
|
|
|
|
# Create the data directory (Cloudron mounts the localstorage volume here)
|
|
RUN mkdir -p /app/data /app/code
|
|
|
|
# Create a startup script that configures LiteLLM with Cloudron addons
|
|
COPY start.sh /app/code/start.sh
|
|
RUN chmod +x /app/code/start.sh
|
|
|
|
# Default config — will be overridden by Cloudron env vars at runtime
|
|
COPY config.yaml /app/data/config.yaml
|
|
|
|
# Override the base image's ENTRYPOINT (which is `litellm`) so our
|
|
# startup script runs instead of being passed as an argument to litellm.
|
|
ENTRYPOINT ["/app/code/start.sh"]
|
|
|
|
# No CORS patch needed since v1.84.0: upstream replaced the hardcoded
|
|
# `origins = ["*"]` with a native LITELLM_CORS_ORIGINS env var (start.sh
|
|
# exports it). The old sed patch targeted a v1.74.0 file layout that no
|
|
# longer exists — the v1.84.0 rebuild self-skipped it correctly.
|